CVE-2023-0035

MEDIUM

OpenHarmony <v3.0.5 - Auth Bypass

Title source: llm
STIX 2.1

Description

softbus_client_stub in communication subsystem within OpenHarmony-v3.0.5 and prior versions has an authentication bypass vulnerability which allows an "SA relay attack".Local attackers can bypass authentication and attack other SAs with high privilege.

Scores

CVSS v3 6.5
EPSS 0.0005
EPSS Percentile 14.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-287 CWE-294
Status published
Products (1)
openatom/openharmony 3.0 - 3.0.5
Published Jan 09, 2023
Tracked Since Feb 18, 2026